CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,133 vulnerabilities with CWE-427
CVE-2025-10213 HIGH
Updf - Uncontrolled Search Path
CVSS 7.8
CVE-2025-10198 HIGH
Lizardbyte Sunshine - Uncontrolled Search Path
CVSS 7.8
CVE-2025-55671 HIGH
TkEasyGUI <1.0.22 - RCE
CVSS 7.8
CVE-2025-9330 HIGH
Foxit PDF Reader - Privilege Escalation
CVSS 7.8
CVE-2025-8614 HIGH
Nomachine < 8.17.2 - Uncontrolled Search Path
CVSS 7.8
CVE-2025-9016 HIGH
Mechrevo Control Center GX V2 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-9000 HIGH
Mechrevo Control Center GX V2 - Uncontrolled Search Path
CVSS 7.0
CVE-2025-49571 HIGH
Adobe Substance 3D Modeler < 1.22.2 - Uncontrolled Search Path
CVSS 7.8
CVE-2025-27717 MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2025-26404 MEDIUM
Intel(R) DSA <25.2.15.9 - Privilege Escalation
CVSS 6.7
CVE-2025-24923 MEDIUM
Intel(R) AI - Privilege Escalation
CVSS 6.7
CVE-2025-22838 MEDIUM
Intel RealSense <2.14.2.0 - Privilege Escalation
CVSS 6.7
CVE-2025-21093 MEDIUM
Intel(R) Driver & Support Assistant Tool <24.6.49.8 - Privilege Esc...
CVSS 6.7
CVE-2025-20627 MEDIUM
Intel(R) oneAPI DPC++/C++ Compiler <2025.0.1 - Privilege Escalation
CVSS 6.7
CVE-2025-20092 MEDIUM
Clock Jitter Tool <6.0.1 - Privilege Escalation
CVSS 6.7
CVE-2025-20048 MEDIUM
Intel(R) Trace Analyzer and Collector - Privilege Escalation
CVSS 6.7
CVE-2025-20017 MEDIUM
Intel(R) oneAPI Toolkit - Privilege Escalation
CVSS 6.7
CVE-2025-30033 HIGH
Setup Component - Code Injection
CVSS 7.8
CVE-2025-53395 HIGH
Paramount Macrium Reflect <2025-06-26 - Code Injection
CVSS 7.7
CVE-2025-53394 HIGH
Paramount Macrium Reflect <2025-06-26 - RCE
CVSS 7.7
CVE-2025-25011 HIGH
Unspecified - Privilege Escalation
CVSS 7.0
CVE-2025-0712 HIGH
Unspecified - Privilege Escalation
CVSS 7.0
CVE-2025-7676 MEDIUM
PE32 Executables - RCE
CVE-2025-7427 MEDIUM
Arm Development Studio <2025 - Local Code Execution
CVSS 5.9
CVE-2025-1729 MEDIUM
TrackPoint Quick Menu - Privilege Escalation
CVSS 6.7
Details
Vulnerabilities 1,133